Status: working towards an ISO/IEC 27001-aligned information security management system. Viewee is not claiming certification.
What the certification requires
ISO/IEC 27001:2022 requires an information security management system (ISMS) that identifies information-security risks, selects and operates proportionate controls, measures performance, corrects problems and improves over time. Certification is performed by an independent certification body; UKAS accredits certification bodies in the UK.
Evidence and controls we need
ISMS scope, interested parties, legal/contractual requirements and leadership responsibilities.
Information-asset register, data flows, risk method, risk register and treatment plan.
Statement of Applicability explaining which Annex A controls apply and why.
Policies and operating evidence for identity/access, cryptography, suppliers, secure development, vulnerability management, logging, incidents, continuity, backups, retention and privacy.
Competence, awareness, document control, objectives and measurable security indicators.
Internal audit, management review, corrective actions and evidence of continual improvement.
Certification readiness for Stage 1 document review and Stage 2 implementation audit, followed by ongoing surveillance.
Current gap status
Good design direction exists for UK/EU processing, managed identity/MFA, separate environments, infrastructure as code, CI/security scanning, encrypted storage, telemetry and structured audit records.
Support-access requirements are defined: time-limited, reasoned, visible, read-only by default, step-up authenticated and audited.
AI safeguards and zero-retention vendor requirements are documented, but no vendor is selected and the DPA/DPIA work remains open.
No formal ISMS scope, risk register, Statement of Applicability, internal audit, management review or operating-evidence set is recorded yet.
No ISO/IEC 27001 certification assessment has taken place.
Next steps
Name the ISMS sponsor and owner; define scope across Viewee's people, marketing site, SaaS, suppliers and development operations.
Complete the DPIA and map legal, regulatory, customer and processor obligations.
Build asset/data-flow registers, risk assessment, treatment plan and Statement of Applicability.
Implement priority controls and retain operating evidence through several review cycles.
Run an internal audit and management review; close corrective actions.
Choose a UKAS-accredited certification body and plan Stage 1 and Stage 2 only when the ISMS is operating.
Official sources
Deeper review additions - 16 September 2026
ISMS requirements to add explicitly
- Use ISO/IEC 27001:2022 with Amendment 1:2024. In the context and interested-party review, determine whether climate change is relevant and whether interested parties have climate-related requirements.
- Define a repeatable risk method and risk acceptance criteria, then maintain a risk register, treatment plan and Statement of Applicability that justifies control inclusion and exclusion.
- Set measurable information-security objectives with owners, resources, dates and evaluation methods. Plan material ISMS changes rather than making them ad hoc.
- Establish document control covering creation, approval, versioning, access, retention and disposal. Keep competence, awareness and communication evidence.
- Operate monitoring and measurement, an objective internal-audit programme, founder management reviews, corrective actions with root-cause analysis, and effectiveness checks before certification audit.
Technology and operating evidence
- Map all relevant Annex A controls, including supplier/cloud security, secure development, environment separation, test data, vulnerability management, configuration, tenant isolation, support access, logging/monitoring, backup/restore, continuity, incident evidence and privacy.
- Commission risk-based independent testing of the internet-facing app/API and cloud configuration before production and after material change. Keep remediation and retest evidence.
- Vendor promises and design direction are not operating evidence. Build a period of tickets, scans, access reviews, restore tests, incident exercises, metrics and corrective-action records.
Certification route
Use a UKAS-accredited certification body whose accredited scope covers ISO/IEC 27001. Plan Stage 1 and Stage 2 only after the ISMS is defined and operating; surveillance follows certification. Viewee remains working towards certification and must not imply that ISO alignment or readiness is certification.
Working source
The clause and evidence tracker is in "ISO 27001 - Requirements" in the Legal folder, grounded in ISO and UKAS official sources.
